BTC $83,315.99 -1.68%
ETH $2,672.29 -0.67%
BNB $764.43 -1.76%
XRP $1.48 -3.39%
SOL $118.15 -4.04%
TRX $0.3361 +0.71%
DOGE $0.0932 -4.15%
ADA $0.2442 -4.51%
BCH $307.07 -8.28%
LINK $14.94 +5.99%
HYPE $87.71 -4.49%
AAVE $146.57 -5.53%
SUI $1.14 -9.13%
XLM $0.2277 +5.04%
ZEC $1,456.93 -9.51%
AAPL $338.31 -0.61%
AMZN $246.23 -1.60%
GOOGL $342.19 -0.62%
MSFT $509.48 -1.55%
META $717.13 -4.26%
NVDA $228.61 +1.40%
TSLA $358.45 -4.01%
SNDK $1,711.08 -4.09%
INTC $115.89 -7.85%
SPCX $146.52 -1.59%
MU $1,054.24 -3.93%
AMD $606.77 -4.37%
BTC $83,315.99 -1.68%
ETH $2,672.29 -0.67%
BNB $764.43 -1.76%
XRP $1.48 -3.39%
SOL $118.15 -4.04%
TRX $0.3361 +0.71%
DOGE $0.0932 -4.15%
ADA $0.2442 -4.51%
BCH $307.07 -8.28%
LINK $14.94 +5.99%
HYPE $87.71 -4.49%
AAVE $146.57 -5.53%
SUI $1.14 -9.13%
XLM $0.2277 +5.04%
ZEC $1,456.93 -9.51%
AAPL $338.31 -0.61%
AMZN $246.23 -1.60%
GOOGL $342.19 -0.62%
MSFT $509.48 -1.55%
META $717.13 -4.26%
NVDA $228.61 +1.40%
TSLA $358.45 -4.01%
SNDK $1,711.08 -4.09%
INTC $115.89 -7.85%
SPCX $146.52 -1.59%
MU $1,054.24 -3.93%
AMD $606.77 -4.37%

ledger

Ledger is a company focused on cryptocurrency hardware wallets, providing secure storage solutions to protect users' digital assets. Its products include the Ledger Nano S and Ledger Nano X, which support multiple cryptocurrencies and enhance security through offline storage of private keys. Ledger's devices are widely used by individual and institutional investors, aiming to prevent hacking and theft of digital assets.
All
Article
Flash

first_img IBM will connect Digital Asset Haven to the Swift shared ledger, supporting tokenized deposit transactions

IBM announced that customers of its digital asset management platform IBM Digital Asset Haven can now connect to permissioned blockchain networks, including the blockchain-based shared ledger from Swift. A new beta version of the ISO 20022 message adapter allows financial institutions to initiate tokenized deposit transactions through this ledger using standard payment messages. IBM stated that financial institutions participating in Swift-related programs have tested tokenized deposits on this ledger using Digital Asset Haven. The ledger supports tokenized deposits issued by banks, enabling participating IBM clients to transfer digital assets around the clock, with final settlement still completed through existing systems.Swift first announced this ledger at Sibos 2025, based on a prototype developed in collaboration with Consensys, with over 40 financial institutions involved in its design, 17 of which are participating in the tokenized deposit pilot. Swift currently connects over 12,500 financial institutions across more than 200 markets worldwide. The aforementioned message adapter allows banks to continue using existing payment message formats and operational processes without adopting blockchain-specific workflows.IBM is also expanding Digital Asset Haven to a localized deployment beta version, which can be installed on IBM Z and IBM LinuxONE in the client's own data center for managing digital assets such as stablecoins and tokenized deposits, without relying on public cloud infrastructure. IBM stated that the platform and key management layer are fully retained within the client's own environment, with keys protected by IBM Crypto Express hardware security modules.

first_img XRP Ledger restarts upgrade, allowing accounts to split payment and compliance permissions

The PermissionDelegationV1_1 upgrade of the XRP Ledger entered a 14-day activation countdown on September 21, having received support from 29 of the 35 trusted validator nodes. If the support rate remains above 80% during this period, the upgrade could officially activate as early as October 5 at 11:18 UTC; at least 28 validator nodes must continue to support it, or the countdown will reset.This feature allows accounts to split permissions by role. For example, a stablecoin issuer can allow a connected compliance system to approve customer accounts holding its tokens while keeping the keys with full control offline; operational accounts can gain payment permissions but cannot change keys or delegate authority to others. Each trustee can have up to 10 permissions, and the main account can modify or revoke them at any time.This is the network's second attempt to introduce this feature. The original version had vulnerabilities that attackers could exploit to make others pay transaction fees with improperly signed transactions, and by repeatedly submitting high-fee transactions, they could deplete the victim's XRP balance. This vulnerability was reported by community testers on September 15, 2025, and validator nodes were advised to reject the amendment, so it was never activated. The fixed version was released with xrpld 3.3.0, changing the way unauthorized transactions are rejected, ensuring that fees are not deducted before signature verification.

Vitalik: Blockchain has evolved from a simple ledger into a cryptography-based secure computing network

Vitalik Buterin, co-founder of Ethereum, delivered a keynote speech at the 12th Global Blockchain Summit, stating that the blockchain was initially a primary tool. Although it has characteristics such as openness, neutrality, and security, it is not scalable and is completely transparent, lacking privacy protection mechanisms.Subsequently, privacy transactions and scalable verification brought by zero-knowledge proofs have changed this situation and have been transformed from planning into actual EIPs, included in the Ethereum roadmap. Technologies such as fully homomorphic encryption are also beginning to be applied, and indistinguishable obfuscation may also be applied on-chain in the future. Beyond privacy, the parallel construction and proof of blocks can make extreme scalability possible, and industry thinking has shifted from digital assets to digital assets plus information, from purely on-chain to user-end, transaction memory pools, a complete pipeline on-chain, and from who can send what to who can see what.Currently, blockchain has gradually evolved from a simple ledger to a cryptography-based secure computing network. With the development of AI, providing cryptographic rules to AI for automated formal verification can significantly enhance verification efficiency, allowing the chain to carry more possibilities.

first_img Ripple: Asset management institutions are preparing for the payment upgrade Batch V1.1 of the XRP Ledger

According to CoinDesk, Ripple stated that asset management companies and other commercial projects are preparing to use the Batch V1.1 feature of the XRP Ledger. This feature allows up to eight transactions to be combined into a single operation and ensures that all transactions either succeed or fail in an all-or-nothing manner, avoiding situations where one party completes settlement while the other fails.This upgrade is expected to support Delivery Versus Payment (DVP) transactions, allowing asset transfers and payments to be completed simultaneously, while also enabling exchanges, wallets, and market platforms to directly attach service fees to customer transactions for processing.RippleX Engineering Director Ayo Akinyele mentioned that some projects are already being developed around Batch, and once activated, it will bring related work closer to a production environment. Specific partners and launch times will be announced once plans are finalized. The amendment has received support from 30 of the 35 tracked validators on the XRP Ledger, exceeding the 28 votes required to enter the activation countdown. The countdown began on September 15, and if the validator support rate remains above 80% within 14 days, Batch V1.1 is expected to be activated shortly after September 29.Previously, researchers discovered serious flaws in the Batch V1 signature verification process in February, which could prematurely stop checking signatures under certain conditions, allowing attackers to unauthorizedly include transactions from other accounts. The developers subsequently withdrew the original version. Since the amendment had not yet been activated at that time, the vulnerability code did not run on the live ledger, and no funds were exposed.

first_img XRP Ledger upgrade Batch V1.1 is just one vote away from activation

The Batch V1.1 upgrade for the XRP Ledger is just one vote away from initiating the activation process. The RippleX team has fixed 11 software defects in the latest review. The Batch feature allows users to combine up to eight related transactions into a single operation, ensuring that both parties complete the transfer simultaneously when two people exchange tokens, thus avoiding the situation where one party pays while the other fails.In Tuesday's snapshot, the upgrade received support from 27 out of 35 trusted validators, accounting for approximately 77%, while changes to the XRP Ledger require an 80% support rate. Therefore, currently, one validator's vote can determine success or failure, and obtaining one more vote will initiate a two-week activation countdown. The support rate must remain above this threshold for 14 days, during which validators can change their votes.Previously, researchers discovered vulnerabilities in the original Batch proposal, allowing attackers to initiate transactions using others' accounts without authorization under specific conditions; this version was not deployed on the mainnet. The new version was released with xrpld 3.3.0 on August 6, and the latest review found 11 issues related to signatures, authorization checks, and server crashes. Among these, a serious vulnerability rated by the security company Common Prefix could allow attackers to reuse user signature permissions to execute transactions beyond expectations. RippleX stated that the review involved four senior engineers, audits from Halborn and Common Prefix, public security competitions, and automated testing, and mentioned that commercial projects using Batch have been signed or are in development.

first_img The U.S. SEC plans to amend the transfer agent rules to allow blockchain ledgers to serve as official records of securities ownership

The U.S. Securities and Exchange Commission (SEC) proposed a new rule last week to comprehensively revise the transfer agent rules that have been in place for decades, explicitly allowing electronic databases, including blockchain ledgers, to serve as the official record of securities ownership for the first time. If approved, blockchain is expected to become the "master security document," replacing the off-chain parallel ownership records that tokenized securities currently rely on.Currently, many tokenized securities operate on two sets of records: on-chain token ledgers and official shareholder registers. Once the proposal is passed, issuers and transfer agents may no longer need to maintain duplicate records and reconcile them after each transfer, thereby reducing operational friction and the risk of inconsistencies between on-chain records and legally recognized records. Eli Cohen, Chief Legal Officer of the tokenized fund platform Centrifuge, stated that this proposal could transform the current "two-step" process into a "one-step" process, allowing the blockchain itself to act as the master security document.However, the proposal does not mean that tokenized securities are completely "permissionless." Joris Delanoue, CEO of the registered on-chain transfer agent Fairmint, pointed out that while the blockchain can remain open, assets must still comply with ownership and transfer rules, and regulatory controls such as identity verification and transfer restrictions are still embedded in the tokens. Transfer agents will still need to handle administrative matters such as shareholder death, inheritance, and legal notifications, with processing times potentially reduced from 3-5 days to 1 day. The 60-day public comment period for the proposal will end in early November.

first_img Ripple has established a four-phase quantum-resistant migration plan for the XRP Ledger

Ayo Akinyele, Senior Director of Engineering at Ripple, stated that the company is developing a four-phase quantum-resistant migration plan for the XRP Ledger, aiming to complete the transition before quantum computers become a real threat. The plan includes assessing the network's exposure, testing quantum-resistant cryptographic solutions, running existing security systems in parallel with quantum-resistant alternatives, and preparing emergency response pathways for scenarios where quantum computing advances exceed expectations.Akinyele emphasized that migration is not just about replacing a cryptographic algorithm, but requires more flexible infrastructure, stronger key management, and clearer upgrade paths. The XRP Ledger has supported changing the keys that control accounts without altering the accounts themselves, a feature that is expected to reduce the difficulty of future migrations, but independent validators on the network still need to coordinate any broader rule changes.Meanwhile, Anthropic's model last month reduced the workload required to break leading post-quantum signature candidates by 67 million times, and Bitcoin and Ethereum developers also released their respective migration plans this week. Akinyele pointed out that AI and quantum computing are different technologies, but they are driving financial infrastructure to evolve in the same direction, as AI agents begin to trade and pay autonomously, raising new requirements for payment infrastructure that is always online and natively internet-based.

first_img OneKey reproduces the transaction replacement attack targeting the old version of the Ledger Ethereum application

The security team of the open-source wallet provider OneKey successfully replicated the exploitation of a vulnerability in the old version of the Ledger Ethereum application in a laboratory environment. OneKey's founder and CEO Wang Yishi stated that they executed a "transaction replacement attack" on Ledger Ethereum application version 1.22.1 by exploiting a previously patched vulnerability, allowing attackers to overwrite pending transactions while users review legitimate transactions.Ledger responded that exploiting this vulnerability requires controlling the communication between the device and the host, such as through malware, compromised wallet software, or malicious web pages. Ledger has added application layer protections in the Ethereum application version 1.22.2 released on August 13 and fixed the underlying issue in Secure SDK 26.6.1 on August 21. Ledger emphasized that no users were hacked as a result; this was merely a replication of the vulnerability in a laboratory environment.This security test occurred after the Coldcard vulnerability incident. Previously, the Coldcard wallet had a firmware vulnerability that posed security risks to some mnemonic phrase generation, but Ledger stated that its devices were not affected by this vulnerability because recovery phrases are generated by a certified random source built into the device's secure chip. The vulnerability replicated by OneKey is unrelated to mnemonic phrase generation but affects the way transactions are processed during the signing process.

Ledger CTO responds to vulnerability FUD: The issue was fixed before it was disclosed, and users can safely use it by updating in a timely manner

Ledger's Chief Technology Officer Charles Guillemet stated that there has recently been "FUD" targeting Ledger in the market, as a smart contract security company claimed to have discovered vulnerabilities in the Ledger Ethereum application. Guillemet mentioned that there indeed were vulnerabilities related to certain Clear Signing processes in the Ledger Ethereum application, but these vulnerabilities were discovered by Ledger's security research team Donjon using AI-driven vulnerability research tools, and the fixes were completed and deployed two weeks ago. Users can obtain protection by timely updating their Ledger device firmware and applications.The relevant security company contacted Ledger's bug bounty program only after the fixes were completed, did not follow responsible disclosure processes, and did not communicate with the bug bounty team, yet implied in subsequent content that the issue had not been resolved. This approach is not true security research but rather a way to create panic for attention. AI is changing the cybersecurity landscape, and both attackers and defenders can enhance efficiency with AI, but AI-driven security research can only truly enhance the security of the entire ecosystem when basic security principles such as responsible disclosure and pre-release verification are followed.Guillemet finally reminded Ledger users to keep their device firmware, Ledger applications, and related software up to date to automatically receive the latest security fixes and research results. Users should not be influenced by the related "FUD" and should timely update their software and maintain safe habits.
app_icon
ChainCatcher Building the Web3 world with innovations.